Ok, this seems to work now. My setup: br0 is my main private network (wl0 plus lan-switch) br1 is connected to my guest network (wl0.1) I only want to isolate the clients inside wl0.1 from each other. In Administration, Scripts, Firewall: Code: wl -i wl0.1 ap_isolate 1 ebtables -I FORWARD -i wl0.1 -o wl0.1 -j DROP Save & reboot router. (I am sure there is a easy way to restart the wl driver, but thats not important right now). Now i have 2 clients, both connected to my wireless guest-network (wl0.1). Ping from Client1 -> Client2: FAIL Ping from Client2 -> Client1: FAIL Ping from Client1 -> Router: WORKING Ping from Client2 -> Router: WORKING Internet access from both clients: WORKING Moved the two clients to my private network (wl0): Ping from Client1 -> Client2: WORKING Ping from Client2 -> Client1: WORKING Exactly as it should be Guest-Clients cannot access each other but surf the web, private clients are not affected and can access whatever they want. Unfortunately i can only test ping right now, no other types of access (both my devices are ipads). But if ping fails, so should pretty much everything else. A very very huge THANK YOU to Trent Bates for investing so much time in finding the right commands!